Love Electric Data Breach: 877,000 Driver Records Allegedly Leaked for $600
On August 26, 2026, a seller using the alias "seraphims" listed a database allegedly belonging to Love Electric, a UK-based broker for electric-vehicle (EV) salary sacrifice schemes, on an English-language data-breach forum. The seller claimed to possess 877,000 records containing sensitive driver information, offering the dataset for $600 in cryptocurrency, with negotiable pricing.
Key Details of the Breach
- Who: Love Electric Financial Services Limited, an Edinburgh-based company registered under SC374952, operates as a salary sacrifice administrator and FCA-regulated credit broker for UK employers.
- What: The leaked sample (999 rows) included names, email addresses, phone numbers, dates of birth, addresses, postcodes, National Insurance numbers (NINo), driving licence numbers, and employer details data typically handled by payroll departments due to salary sacrifice arrangements.
- When: The seller claimed the breach occurred in August 2026, allegedly via a zero-day exploit in a third-party system. However, timestamps in the sample suggest the records were created in a six-second window on August 14, 2022, indicating legacy data rather than a recent attack.
- Where: The data appears to originate from a Microsoft SQL Server database, with postcodes clustering around Edinburgh and central Scotland, extending into England.
- Why: The seller’s motives remain unclear, but the low asking price ($600) suggests a quick sale rather than a high-value ransom demand. The data’s sensitivity including unchangeable identifiers like NINo and driving licence numbers heightens risks of phishing, identity theft, and fraud.
Verification and Data Authenticity
Researchers at Ransomnews analyzed the sample and found strong evidence of legitimacy:
- Structural integrity: The 999 rows split into 731 primary drivers and 268 additional named drivers, with consistent relationships (e.g., National Insurance numbers only on primary drivers, no orphaned records).
- Real-world patterns: The data contained user errors (e.g., mismatched licence numbers, inconsistent phone formats) and corporate email domains, aligning with workplace salary sacrifice schemes.
- Geographic and demographic logic: Dates of birth ranged from 1946 to 1999, with concentrations in the 1970s–1980s, and postcodes matched Love Electric’s operational footprint.
- Technical validation: Of 108 full-length UK driving licence numbers in the sample, 98.1% matched surnames, 97.2% matched first-name initials, and 78.7% aligned with stored birthdates error rates consistent with real user input.
However, the 877,000-record claim remains unverified. The sample represented only 0.11% of the alleged dataset, and the db2_ prefix in the filename suggests the table may be part of a larger collection. Additionally, the seller’s account (seraphims), created on July 22, 2026, had a low reputation score (30) and a history of listing scraped data, casting doubt on the scale of the breach.
Impact and Risks
- Identity theft: NINo and driving licence numbers are permanent identifiers, making them prime targets for fraud.
- Phishing: Attackers could craft convincing impersonation scams (e.g., posing as HMRC, employers, or leasing providers) using the leaked details.
- Employer exposure: Love Electric works with over 1,500 companies, amplifying the potential fallout for businesses and employees.
- Data proliferation: The low sale price increases the risk of multiple buyers accessing the same data, prolonging exposure.
Love Electric was contacted for comment but had not responded at the time of publication. Ransomnews shared the sample with Love Electric’s incident-response team before reporting, without accessing the full dataset or probing the company’s systems.
The incident underscores the identity risks posed by third-party salary sacrifice providers, where sensitive data is often aggregated across employers. While the seller’s zero-day claim remains unconfirmed, the authenticity of the sample raises urgent concerns for affected individuals and organizations.
Love In the Name of Christ cybersecurity rating report: https://www.rankiteo.com/company/love-inc
"id": "LOV1787956759",
"linkid": "love-inc",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '877,000 (alleged)',
'industry': 'Financial Services / EV Salary Sacrifice '
'Broker',
'location': 'Edinburgh, UK',
'name': 'Love Electric Financial Services Limited',
'type': 'Company'}],
'attack_vector': 'Zero-day exploit in a third-party system',
'data_breach': {'data_exfiltration': 'Yes (alleged)',
'number_of_records_exposed': '877,000 (alleged)',
'personally_identifiable_information': ['Names',
'Email addresses',
'Phone numbers',
'Dates of birth',
'Addresses',
'Postcodes',
'National Insurance '
'numbers',
'Driving licence '
'numbers'],
'sensitivity_of_data': 'High (unchangeable identifiers)',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)',
'National Insurance numbers '
'(NINo)',
'Driving licence numbers',
'Employer details']},
'date_detected': '2026-08-26',
'date_publicly_disclosed': '2026-08-26',
'description': "A seller using the alias 'seraphims' listed a database "
'allegedly belonging to Love Electric, a UK-based broker for '
'electric-vehicle (EV) salary sacrifice schemes, on an '
'English-language data-breach forum. The seller claimed to '
'possess 877,000 records containing sensitive driver '
'information, offering the dataset for $600 in cryptocurrency. '
'The leaked sample included names, email addresses, phone '
'numbers, dates of birth, addresses, postcodes, National '
'Insurance numbers (NINo), driving licence numbers, and '
'employer details.',
'impact': {'brand_reputation_impact': 'High (identity theft and fraud risks)',
'data_compromised': '877,000 records (alleged)',
'identity_theft_risk': 'High (NINo, driving licence numbers '
'exposed)',
'legal_liabilities': 'Potential (FCA-regulated entity)',
'systems_affected': 'Microsoft SQL Server database'},
'initial_access_broker': {'data_sold_on_dark_web': 'Yes (alleged)'},
'investigation_status': 'Ongoing (sample verified, full dataset unverified)',
'lessons_learned': 'The incident underscores the identity risks posed by '
'third-party salary sacrifice providers, where sensitive '
'data is often aggregated across employers. The '
'authenticity of the sample raises urgent concerns for '
'affected individuals and organizations.',
'motivation': 'Financial gain (data sale)',
'post_incident_analysis': {'root_causes': 'Potential zero-day exploit in a '
'third-party system (unconfirmed)'},
'references': [{'date_accessed': '2026-08-26', 'source': 'Ransomnews'}],
'regulatory_compliance': {'regulations_violated': ['Potential FCA regulations '
'(UK)',
'Data Protection Act 2018 '
'/ UK GDPR']},
'response': {'third_party_assistance': 'Ransomnews (sample analysis)'},
'threat_actor': 'seraphims (alias)',
'title': 'Love Electric Data Breach: 877,000 Driver Records Allegedly Leaked '
'for $600',
'type': 'Data Breach',
'vulnerability_exploited': 'Zero-day exploit'}